For Trellix DLP – SaaS to retrieve user information and logon data from Trellix Logon Collector, you must first install and configure Trellix Logon Collector.
You can download the Trellix Logon Collector from the Trellix product downloads portal (https://www.trellix.com/en-us/downloads.html).
Trellix Logon Collector needs a Windows 2008 R2 or later version of Windows Server. For more information about installing Trellix Logon Collector, see the Trellix Logon Collector Administration Guide.
Accessing Trellix Logon Collector interface
Trellix Logon Collector has a web-based user interface for configuration and management. After you install Trellix Logon Collector, you can access its user interface using this URL:
https://mlc.host.name:8443
What is Logon Monitor?
Logon Monitor is the component of Trellix Logon Collector that monitors and receives security events. Trellix Logon Collector has a built-in Logon Monitor.
You can install Logon Monitors separately and so when adding domains to Managed Domains, you can select Logon Monitors as needed for monitoring security events.
For more information about installing Logon Monitors, see the Trellix Logon Collector Administration Guide.